CVE-2020-9961: Input Validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.
Other sources
ImageIO. An out-of-bounds read was addressed with improved input validation.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9979
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-9960
- CVE-2020-9954
- CVE-2020-9949
- CVE-2020-9999
- CVE-2020-9965
- CVE-2020-9966
- CVE-2020-29629
- CVE-2020-9956
- CVE-2020-9962
- CVE-2020-27931
- CVE-2020-29639
- CVE-2020-9978
- CVE-2020-36521
- CVE-2020-9961
- CVE-2020-9955
- CVE-2020-9876
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-9976
- CVE-2020-9981
- CVE-2020-9971
- CVE-2020-9969
- CVE-2020-9968
- CVE-2020-13434
- CVE-2020-13435
- CVE-2020-9991
- CVE-2020-15358
- CVE-2020-13631
- CVE-2020-9849
- CVE-2020-13630
- CVE-2020-9947
- CVE-2020-9950
- CVE-2020-9951
- CVE-2020-9983
- CVE-2020-9952
- CVE-2020-10013
- CVE-2020-9986
- CVE-2020-9941
- CVE-2020-10011
- CVE-2020-9973
- CVE-2020-13520
- CVE-2020-9989
- CVE-2020-9946
- CVE-2020-9993
- CVE-2020-10002
- CVE-2020-27912
- CVE-2020-27917
- CVE-2020-27911
- CVE-2020-27918
- CVE-2020-9958
- CVE-2020-9773
- CVE-2020-9992
- CVE-2020-9964
- CVE-2019-14899
- CVE-2020-9988
- CVE-2020-6147
- CVE-2020-9972
- CVE-2020-9996
- CVE-2020-9963
- CVE-2020-9977
- CVE-2020-9959
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-9961.
What is the affected software?
The affected software includes Apple tvOS up to version 14.0, Apple iOS up to version 14.0, Apple iPadOS up to version 14.0, Apple macOS Catalina up to version 10.15.7, Apple High Sierra, Apple Mojave, Apple watchOS up to version 7.0, Apple iTunes for Windows up to version 12.10.9, and Apple iCloud for Windows up to version 11.5.
What is the severity of CVE-2020-9961?
The severity of CVE-2020-9961 is not mentioned in the provided information.
What is the remediation for this vulnerability?
Update the affected software to the latest version provided by Apple.
Where can I find more information about CVE-2020-9961?
You can find more information about CVE-2020-9961 on the Apple support website. Here are the references: [link1], [link2], [link3]